It looks like I can use a non-internal network with no default route I guess? But then the containers can access ports on the host so I guess I need to firewall-cmd those off...
And also there's a DNS hole (the podman DNS server will still resolve external DNS names)... I have no idea how to disable that.
